Supervised mobile devices with iOS 9.3 or later, or iPadOS 9.3 or later
Supervised Apple TV devices with tvOS 11 or later
You must create separate profiles for the safelist and blocklist configurations on mobile devices.
- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click + Create Profile.
- Select the iOS or tvOS operating system.
- (For iOS profiles only) Select the Device Enrollment enrollment type.
- Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
- Click Finish.
- In the list of payloads on the left side of the pane, locate the iOS payload (Supervised only) or tvOS payload (Supervised only) category depending on the operating system of the devices you are configuring a profile for and click the Safelist and Blocklist payload.
- Click Configure.
- To configure a safelist, do the following:
- From the Safelist/Blocklist Applications pop-up menu, choose "Allow safelisted apps and categories".
- Select one or more app categories to add to the safelist. Apps belonging to the selected categories will be added to the safelist automatically.
- Click Add Application to select one or more apps to add to the safelist. You can choose from default Apple apps, managed apps, and apps available in the App Store.Note:
If you cannot find an app when searching by its name on the Search the AppStore tab of the pop-up dialog, search for the app by its ID number instead. To obtain an app's ID number, locate the app in the App Store and copy the app's preview link using the Share icon in the upper-right corner (e.g., https://apps.apple.com/us/app/jamf-parent/id1458797105). Then paste the app's preview link (e.g., in a web browser) and copy the ID number from the URL (e.g., 1458797105).
- (Optional) To safelist all web clips on devices, select the Safelist all web clips checkbox.
- (Optional) To allow users to sign in with iCloud and Google accounts on devices, select the Enable iCloud and Google account sign-ins checkbox.Note:
Selecting the Enable iCloud and Google account sign-ins checkbox adds
com.apple.CoreCDPUI.localSecretPromptto the safelist.
- To configure a blocklist, do the following:
- From the Safelist/Blocklist Applications pop-up menu, choose "Restrict blocklisted apps and categories".
- Select one or more app categories to add to the blocklist. Apps belonging to the selected categories will be added to the blocklist and hidden from devices automatically.
- Click Add Application to select one or more apps to add to the blocklist. You can choose from default Apple apps, managed apps, and apps available in the App Store.Note:
If you cannot find an app when searching by its name on the Search the AppStore tab of the pop-up dialog, search for the app by its ID number instead. To obtain an app's ID number, locate the app in the App Store and copy the app's preview link using the Share icon in the upper-right corner (e.g., https://apps.apple.com/us/app/jamf-parent/id1458797105). Then paste the app's preview link (e.g., in a web browser) and copy the ID number from the URL (e.g., 1458797105).
- (Optional) To prevent the installation of App Store apps on devices, select the Disallow installation of new apps from the App Store checkbox.
- (Optional) To blocklist all web clips on devices, select the Blocklist all web clips checkbox.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu. For more information, see Device Groups.
- Click the Settings
icon on the right side of the page, and do one of the following:
To install the profile on devices automatically, click Change to automatic installation for all groups.
To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.
- Click Save.